PowerSpider 3.10 Server
(Backdoor.Win32.PowerSpider.310)

by MiniSnake

Written in Visual C++

Made in China

more versions


dropped files:
c:\WINDOWS\system32\iexplore .exe             Size: 56,256 bytes 
c:\WINDOWS\system32\psinthk.dll               Size: 7,168 bytes 
c:\WINDOWS\system32\pwdbox-003_r.exe          Size: 1,612 bytes 
c:\WINDOWS\system32\xikecn2002_163_com.exe    Size: 1,612 bytes 

port: 1044 TCP

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices "mssysint"
data: iexplore .exe 



tested on Windows XP
March 04, 2006

MegaSecurity